Challenge : Let say I want a to replace Fiber Connection with Site VPN, hosted through ISP.New Situation :Core Switch connected to Serverroom switch. Firewall Is connected to serverroomswitch and has a Site VPN tunnel to a remote location and terminated to edge switch.

How can I still have everything such as VLAN / DHCP VRRP etc to work just a my current network ? I have an idea, but want to validate.

Should the management VLAN just be replaced so it can reach the Coreswitch and vice versa ?

Most VPN's are L3 VPN's which means you loose any L2 functions such as VLAN's, VRRP. There are L2 VPN's (I see them over MPLS circuits a lot), so make sure what kind you have. If it's L3 then you have a router now at each location. That router needs to be programmed with the DHCP relay info. Of course you need two routers to run VRRP at each location. You also have to deal with distributing your routing table to the new routers.

It all comes down to what kind of WAN-connection you get through your ISP. If they give you a L2-connection, then you can use it as an extension of your LAN/MAN, and just use L2/L3 capable devices like the ERS5500-series (and all the other ERS-series switches). If they provide a managed L3 VPN, all L3 features will need to be provided on the providers CE-equipment (router).

One thing you may want to start thinking of, given that your provider has an L2-connection, is to set up a SPB network with VSP4000s at the central and remote site. Then you will be in full control of all aspects, both L2 and L3